From 618920f01b65dfeffe76092057998808163ccb11 Mon Sep 17 00:00:00 2001 From: Jiri Popek Date: Thu, 25 Jul 2019 13:35:11 +0200 Subject: Add option to set owner group of daemon FIFO (#122) New option to set owner group of daemon FIFO (Default: /tmp/dlt) is added in dlt.conf. If this option is used properly, more secure tracing can be realized. Only application that is in dlt_user_apps_group can write log message to daemon FIFO. Signed-off-by: Yusuke Sato --- src/daemon/dlt-daemon.c | 38 +++++++++++++++++++++++++++++++++++++- 1 file changed, 37 insertions(+), 1 deletion(-) (limited to 'src/daemon/dlt-daemon.c') diff --git a/src/daemon/dlt-daemon.c b/src/daemon/dlt-daemon.c index 7b80ef1..c305887 100644 --- a/src/daemon/dlt-daemon.c +++ b/src/daemon/dlt-daemon.c @@ -39,6 +39,7 @@ #include #include #include +#include #ifdef linux # include @@ -253,7 +254,8 @@ int option_file_parser(DltDaemonLocal *daemon_local) if (strlen(DLT_USER_IPC_PATH) > DLT_IPC_PATH_MAX) fprintf(stderr, "Provided path too long...trimming it to path[%s]\n", daemon_local->flags.appSockPath); - +#else + memset(daemon_local->flags.daemonFifoGroup, 0, sizeof(daemon_local->flags.daemonFifoGroup)); #endif daemon_local->flags.gatewayMode = 0; strncpy(daemon_local->flags.gatewayConfigFile, @@ -566,6 +568,11 @@ int option_file_parser(DltDaemonLocal *daemon_local) intval); } } + else if(strcmp(token, "DaemonFifoGroup") == 0) + { + strncpy(daemon_local->flags.daemonFifoGroup, value, NAME_MAX); + daemon_local->flags.daemonFifoGroup[NAME_MAX] = 0; + } else if (strcmp(token, "BindAddress") == 0) { DltBindAddress_t *newNode = NULL; @@ -1085,6 +1092,35 @@ static int dlt_daemon_init_fifo(DltDaemonLocal *daemon_local) return -1; } /* if */ + /* Set group of daemon FIFO */ + if (daemon_local->flags.daemonFifoGroup[0] != 0) + { + errno = 0; + struct group * group_dlt = getgrnam(daemon_local->flags.daemonFifoGroup); + if (group_dlt) + { + ret = chown(tmpFifo, -1, group_dlt->gr_gid); + if (ret == -1) + { + dlt_vlog(LOG_ERR, "FIFO user %s cannot be chowned to group %s (%s)\n", + tmpFifo, daemon_local->flags.daemonFifoGroup, + strerror(errno)); + } + } + else if ((errno == 0) || (errno == ENOENT) || (errno == EBADF) || (errno == EPERM)) + { + dlt_vlog(LOG_ERR, "Group name %s is not found (%s)\n", + daemon_local->flags.daemonFifoGroup, + strerror(errno)); + } + else + { + dlt_vlog(LOG_ERR, "Failed to get group id of %s (%s)\n", + daemon_local->flags.daemonFifoGroup, + strerror(errno)); + } + } + fd = open(tmpFifo, O_RDWR); if (fd == -1) { -- cgit v1.2.1